Back to search
Jeavio Linkedin · Posted yesterday

Manager - Internal IT & Information Security

India

Linkedin
Continue to application Add your email once, then Caio opens the original posting.

Indexed description

Jeavio is an ISO 27001 certified software development services company. This role leads the day-to-day operation of our internal IT environment and Information Security Management System (ISMS), ensuring our people can work securely and reliably while maintaining the controls, evidence and readiness expected by our clients and auditors. The role partners closely with Engineering, HR, Legal and leadership; governance and final risk acceptance remain with the Information Security Steering Committee.


Key Responsibilities

Internal IT

Lead a reliable, secure and well-managed corporate technology environment for Jeavio’s hybrid workforce.

1. Identity, Endpoints and Access

  • Own Google Workspace, user lifecycle, SSO/MFA, privileged access and periodic access reviews; maintain secure endpoint standards, asset inventory, MDM, encryption and endpoint protection.

2. Infrastructure, Network and Resilience

  • Oversee office and remote connectivity, firewalls, VPN, internal cloud/server environments, backups, recovery, logging and monitoring; maintain appropriate hardening, patching and vulnerability remediation practices.

3. IT Service Management

  • Run the IT support function with clear service levels, prioritization and measurable performance; maintain practical change, incident and problem-management processes and a useful knowledge base.


Information Security and the ISMS

1. ISO 27001 / ISMS Management

  • Operate and continuously improve the ISO/IEC 27001:2022 ISMS, including the Statement of Applicability, required documentation, management reviews, control ownership and action tracking.
  • Coordinate certification, surveillance and internal audit activities; ensure findings and corrective actions are driven to effective closure.

2. Risk, Policy and Compliance

  • Maintain the information security risk register and treatment plans, assess material changes, and present significant or residual risks to the Steering Committee for decision.
  • Keep security policies and standards current and practical; manage security exceptions, awareness activities and applicable legal, contractual and client security obligations.

3. Security Assurance and Client Readiness

  • Coordinate vulnerability assessments and penetration testing, verify remediation, and work with Engineering on appropriate security expectations for development environments, repositories, pipelines and secrets.
  • Support client security questionnaires, due-diligence reviews and audits with clear, evidence-based responses.

4. Incident Response, Continuity and Data Protection

  • Own the security incident response process, including triage, coordination, recovery, post-incident review and timely escalation of contractual or regulatory notification requirements.
  • Maintain appropriate business continuity, disaster recovery, data classification, retention, secure deletion, DLP and client-data handling controls, with periodic testing and review.


Qualifications and Experience

Essential

  • 10+ years of experience across IT infrastructure and/or information security, including 4+ years in a leadership role.
  • Hands-on experience operating an ISO/IEC 27001 ISMS through a certification, surveillance or recertification cycle.
  • Strong working knowledge of identity and access, endpoint security, network/infrastructure security, backup/recovery and vulnerability management in a hybrid environment.
  • Experience working with Google Workspace and/or Microsoft 365 at organisational scale.
  • Ability to work confidently with auditors, clients and internal stakeholders, translating security requirements into practical actions.
  • A degree in Computer Science, IT or Engineering is useful but not required; relevant experience and demonstrated ownership matter more.


Preferred

  • ISO 27001 Lead Implementer/Lead Auditor, CISM, CISSP or CISA certification.
  • Experience in a software services or multi-client environment; exposure to SOC 2, GDPR, India & USA data-protection requirements or major cloud platforms is beneficial.


What Success Looks Like

  • A secure, dependable IT environment with responsive support and clear ownership.
  • An ISMS that is practical, current, audit-ready and supported by evidence rather than paperwork for its own sake.
  • Strong collaboration across Engineering and business teams, balancing security rigour with productivity and sound judgement.
Free. 20 seconds. No password. See every match in this search.

Create a free Caio profile to unlock more results and save your role and location preferences.

Unlock free search
Want help applying to roles like this? Search Caio for free. If repetitive applications get heavy, Managed Job Search adds supervised execution for $99/month.
View Managed Job Search